<?xml version="1.0" encoding="UTF-8"?> 
<?xml-stylesheet href="https://dev.horde.org/themes/horde//default/feed-rss.xsl" type="text/xsl"?> 
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"> 
 <channel> 
  <title>It&#039;s possible to inject javascript on Kronolith</title> 
  <pubDate>Fri, 10 Apr 2026 00:42:31 +0000</pubDate> 
  <link>https://bugs.horde.org/ticket/8552</link> 
  <atom:link rel="self" type="application/rss+xml" title="It&#039;s possible to inject javascript on Kronolith" href="https://bugs.horde.org/ticket/8552/rss" /> 
  <description>It&#039;s possible to inject javascript on Kronolith</description> 
 
   
   
  <item> 
   <title>When a new event is created, it&#039;s possible to inject javascr</title> 
   <description>When a new event is created, it&#039;s possible to inject javascript (at least in the Title field)</description> 
   <pubDate>Fri, 04 Sep 2009 16:44:46 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/8552#t55662</link> 
  </item> 
   
  <item> 
   <title>Changes have been made in Git for this ticket:

Element.upda</title> 
   <description>Changes have been made in Git for this ticket:

Element.update() and Element.insert() don&#039;t escape content and eval scripts automatically. Escape any plain text being inserted (Bug #8552).

http://git.horde.org/diff.php/kronolith/js/kronolith.js?rt=horde-git&amp;r1=fabc16d8ac224bbcf5fbe2f5ff4ac26af563d69c&amp;r2=62b96aed490816b1f2a5c7334ab21bb324455df9</description> 
   <pubDate>Wed, 13 Jan 2010 00:11:03 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/8552#t57608</link> 
  </item> 
   
   
 
 </channel> 
</rss> 
